All templates

Automated AssemblyAI API Key Reviews

Every Monday, WebRun opens AssemblyAI, lists every live API key with its usage and the account member who holds it, writes the review into Google Sheets, and sends you a Telegram list of keys with no traffic and keys nobody claims.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 AssemblyAI review keys, owners, and usage
2 Google Sheets record usage per key
3 Telegram send the revoke shortlist
In short

How do I audit which API keys are still live and who owns them?

WebRun audits your AssemblyAI access every Monday. It lists each live API key with its 30 day usage and the account member who holds it, records the inventory in Google Sheets, and sends you a Telegram shortlist of quiet or unclaimed keys to revoke before one leaks.

  • Unused credentials are named every Monday instead of living forever
  • Every live key has a recorded owner
  • Spend per key is visible next to the key that caused it

Built for engineering leads · platform teams · security engineers · startup CTOs

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens app.assemblyai.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    AssemblyAI - review keys, owners, and usage
    assemblyai.com
    WebRun in AssemblyAI: review keys, owners, and usage
    WebRun opens AssemblyAI to review keys, owners, and usage.
    • Open AssemblyAI and list every API key currently active on the account
    • Read transcription volume and billing attributed to each key over the past 30 days
    • List the account members with access and match each key to the person or service that uses it
    • Mark keys with no traffic in 30 days and keys with no clear owner

    Done when Every live key has a usage figure and an owner, or is marked unclaimed.

  3. 2
    Google Sheets - record usage per key
    google.com
    WebRun in Google Sheets: record usage per key
    WebRun opens Google Sheets to record usage per key.
    • Write one row per key with its owner, last activity, 30 day volume, and spend
    • Add this week as a new dated block so usage per key can be compared over time
    • Highlight rows where a key went from busy to silent

    Done when The sheet holds this week's key inventory alongside the earlier weeks.

  4. 3
    Telegram - send the revoke shortlist
    telegram.org
    WebRun in Telegram: send the revoke shortlist
    WebRun opens Telegram to send the revoke shortlist.
    • Send a short Telegram message listing keys with no traffic and keys nobody claims
    • Put the highest spending unclaimed key first
    • Leave revocation to a human. WebRun never deletes, rotates, or regenerates a key

    Done when You have this week's revoke shortlist in Telegram.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
app.assemblyai.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Key review · Telegram
OutputWhat each run produces - A weekly inventory of live API keys with owner, last activity, volume, and spend, plus a shortlist of keys to revoke.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it revoke or rotate a key on its own?

No. WebRun only reports which keys are quiet or unclaimed. Revoking, rotating, or regenerating a credential is always done by a person, so nothing in production breaks unannounced.

Does the key value itself get written anywhere?

No. WebRun records the key name, owner, usage, and spend. The secret value is never copied into the sheet or into the Telegram message.

How does it decide a key is unused?

It reads the transcription volume and billing attributed to each key over the past 30 days and flags any key with no traffic in that window.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.